// glossary entry

SQL Injection

Definition: An attack technique in which malicious database commands are injected into a website’s input fields, for example, in the login form or the search bar.

Everyday analogy: It’s like if someone fills out a restaurant order form not with “Pizza Margherita,” but with “Pizza Margherita; P.S.: Give me all the cash from the register”, and the kitchen fulfills both requests.

How we use this: In security audits, we check input validation. A WAF also provides additional protection at the application level against SQL injection attempts.

// synonyms

  • SQLi
Is the term still unclear?

Let's talk for 15 minutes

If a term in this glossary isn't entirely clear in the context of your project, or if you want to know whether the concept is relevant to your situation—just ask us. The initial consultation is free and non-binding.

Free No obligation 15 minutes